DSA-6378-1 chromium - security update
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. https://security-tracker.debian.org/tracker/DSA-6378-1
CSIRTS triage
- What
- Security issues could result in the execution of arbitrary code, denial of service, or information disclosure.
- Who is affected
- Users of Chromium.
- Urgency
- Remediation is urgent due to the potential for arbitrary code execution and denial of service.
- Action
- Update to the latest version of Chromium.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Chromium
Get an email when a new Chromium advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://lists.debian.org/debian-security-announce/2026/msg00289.html
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-132810.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-132820.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-132830.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-137740.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-137750.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-137760.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-137770.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-137780.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-137790.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-137800.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownMultiple vulnerabilities in Palo Alto Networks products (August 13, 2026)cert-fr-avis
- highPAN-SA-2026-0011 Chromium: Monthly Vulnerability Update (August 2026) (Severity: HIGH)paloalto
- high[UPDATE] [high] Google Chrome: Multiple vulnerabilitiescert-bund
- unknownMultiple Vulnerabilities in Microsoft Edge (July 29, 2026)cert-fr-avis
- high[UPDATE] [high] Google Chrome: Multiple vulnerabilities allow unspecified attackcert-bund
- unknownMultiple vulnerabilities in Microsoft Edge (July 15, 2026)cert-fr-avis
- unknownCVE-2026-13829: Chromium: CVE-2026-13829 Insufficient validation of untrusted input in Settingsmsrc
- unknownCVE-2026-13811: Chromium: CVE-2026-13811 Use after free in IMEmsrc
- unknownCVE-2026-13817: Chromium: CVE-2026-13817 Insufficient validation of untrusted input in Glicmsrc
- unknownCVE-2026-13782: Chromium: CVE-2026-13782 Use after free in Browsermsrc
- unknownCVE-2026-13783: Chromium: CVE-2026-13783 Use after free in Viewsmsrc
- unknownCVE-2026-13787: Chromium: CVE-2026-13787 Use after free in Chromotingmsrc
More from Debian Security Advisories
- unknownDSA-6464-1 erlang - security update2026-08-25
- unknownDSA-6465-1 openssl - security update2026-08-25
- unknownDSA-6466-1 linux - security update2026-08-25
- unknownDSA-6462-1 zfs-linux - security update2026-08-24
- unknownDSA-6463-1 webkit2gtk - security update2026-08-24